Educause Security Discussion mailing list archives
Re: Password Changes
From: "Bristol, Gary L." <gbristol () OU EDU>
Date: Mon, 16 Aug 2021 20:41:23 +0000
If you don't want to click on the link, I used these terms to find the document link from Microsoft "password history and time limit on password change" From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Bristol, Gary L. Sent: Monday, August 16, 2021 3:39 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Password Changes Here is a document link for Microsoft that talks about Password History and minimum age and best practices. https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/enforce-password-history<https://urldefense.proofpoint.com/v2/url?u=https-3A__docs.microsoft.com_en-2Dus_windows_security_threat-2Dprotection_security-2Dpolicy-2Dsettings_enforce-2Dpassword-2Dhistory&d=DwMFAg&c=qKdtBuuu6dQK9MsRUVJ2DPXW6oayO8fu4TfEHS8sGNk&r=n7xJg_eNKF-qpF5mL-g_1w&m=Lr_b0f7cnIQZNFg1DpXIjUyA7i-naRZcIKqOTvVv_DM&s=VIkL4nPTsl6GeAw0FDj233ZhzyNuKyKxbOKH1o0WaZI&e=> From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Moyer, Janice Sent: Monday, August 16, 2021 2:52 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] Password Changes We only allow 1 password change a day coupled with a password history of 12. Sorry I have no guidelines I can point you to. In addition, we implemented Okta's "Common Password Check" which does not allow a user to set a password to one that matches a list of commonly used passwords. From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Dr. Christopher Davis Sent: Monday, August 16, 2021 2:10 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: [SECURITY] Password Changes CAUTION: This email originated from outside Metropolitan Community College. Do not click links or open attachments unless you recognize the sender and know the content is safe. Forward suspicious items to reportsuspicious () mccneb edu<mailto:reportsuspicious () mccneb edu> or use the "Report Suspicious" button.. How often do you allow your users to change their passwords in a day? Do you actually limit that? If so, is a NIST or other guideline that you are following for that? Thanks! Pax Christi, Dr. Chris Davis Director of Information Technology Services [cid:image001.png@01D792B5.2A5C0AD0] Franciscan University of Steubenville 1235 University Blvd. Steubenville, OH 43952 740-284-5192 cdavis () franciscan edu<mailto:cdavis () franciscan edu> "The body was made for the sake of the soul, and this world for the sake of the other world." St. Giles ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMGaQ&c=vMfcx96HwL1EWlh7C08MXw&r=a8BwapXY5nFTmGR1CH0kMxGaT-h42P6s5Uq2hcs55dY&m=I8psc-XujhZk4b7-_LuLGaSDZotI3aeW2YF0o5uqBSM&s=CB4Wb7n_7cjPUvuSBLYOLyIiYBB7922a9ZMk2xf11MY&e=> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMGaQ&c=qKdtBuuu6dQK9MsRUVJ2DPXW6oayO8fu4TfEHS8sGNk&r=n7xJg_eNKF-qpF5mL-g_1w&m=RWf_64Rl_V2WUM5b7e4i8OV5Y2F70bu16msJ6g-JS-M&s=LYI8kFzacet7KZDyEBvhqdp0T-jF9fDr8S0c5eBtXCw&e=> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=qKdtBuuu6dQK9MsRUVJ2DPXW6oayO8fu4TfEHS8sGNk&r=n7xJg_eNKF-qpF5mL-g_1w&m=Lr_b0f7cnIQZNFg1DpXIjUyA7i-naRZcIKqOTvVv_DM&s=t7RM2ij38Ftw2RT6OjDyD-goEUh_jV2xqOcD92d9mRM&e=> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Password Changes Dr. Christopher Davis (Aug 16)
- Re: Password Changes Moyer, Janice (Aug 16)
- Re: Password Changes Bristol, Gary L. (Aug 16)
- Re: Password Changes Bristol, Gary L. (Aug 16)
- Re: Password Changes Bristol, Gary L. (Aug 16)
- Re: Password Changes Moyer, Janice (Aug 16)